Impact
The kernel’s NFS server routine used during inter‑server copy operations contains a flaw: when nfsd4_setup_inter_ssc() fails, the subsequent nfsd4_copy() returns nfserr_offload_denied immediately, bypassing the normal release path for the nf_dst reference taken earlier, resulting in a leaked nfsd_file object and keeping the associated file, inode, dentry, and vfsmount pinned in memory. Repeated failures could accumulate leaked references and eventually lead to memory pressure or system instability, a vulnerability identified as CWE‑911. Based on the description, it is inferred that an attacker would need the ability to send failing inter‑server COPY requests to the NFS server, which typically requires authentication or local access to the NFS service.
Affected Systems
All Linux kernel builds that include the NFS server component are affected, regardless of distribution, because the vulnerability resides in the generic kernel source. Administrators should verify whether the kernel contains the unpatched code path. Distribution maintainers typically publish updates that include the fix, so checking vendor security advisories for an updated kernel patch is recommended.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity flaw. The EPSS score of less than 1% suggests the vulnerability is unlikely to be abused at present, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require triggering a failing inter‑server COPY operation, which only occurs when a client or internal process initiates that request. Thus, the attack would likely need authentication to the NFS service or local privilege on the server. If successful, leaked references persist until the system is rebooted or the kernel is patched.
OpenCVE Enrichment
Debian DSA